T09 · Insecure Skill Coding Practices
- Location
eval-viewer/generate_review.py:279- Finding
Stored Script Injection in Generated Review Pages
- Content
View full analysis
` element in `viewer.html`. JSON string encoding does not make data safe for placement inside an HTML script element. In particular, it does not neutralize the HTML closing sequence ``. If attacker-controlled review data contains a payload such as: ```html ` breakout payload. 3. `embed_file()` reads that output and includes it in the `embedded` data structure. 4. `generate_html()` serializes the structure and inserts it directly into the executable script context. 5. The user opens the generated static review page or the locally served viewer. 6. The browser parses and executes the injected JavaScript. 7. The payload can read embedded prompts, outputs, grades, benchmark data, and other inf ...[truncated 944 chars]- Remediation
View remediation
``` Before embedding it, escape at least `<`, `>`, `&`, U+2028, and U+2029. For example, replace `<` with `\u003c` so `` cannot be recognized by the HTML parser. 3. Alternatively, Base64-encode the complete JSON document, place only the Base64 alphabet in the page, and decode and parse it as data at runtime. 4. Add a restrictive Content Security Policy. Prefer a nonce- or hash-based `script-src` policy and disallow arbitrary inline scripts. 5. Avoid dynamically constructing HTML where DOM APIs and `textContent` can be used. 6. Add regression tests containing: - `` - Mixed-case closing tags. - HTML comments and malformed script-closing sequences. - Payloads in prompts, text outputs, grading evidence, benchmark notes, and previous feedback. 7. Treat every evaluated output as untrusted, even when it was generated locally. ]]>
